Inception
Also known as: Inception Framework · Cloud Atlas
Overview
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.
Naming & attribution
Inception is tracked under 3 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here. Activity attributed since at least 2014.
| Name | First reported by |
|---|---|
| Inception Framework | Symantec |
| Cloud Atlas | GReAT |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Sidewinder India — 13 shared techniques (33% overlap)
- Confucius — 10 shared techniques (32% overlap)
- APT33 Iran — 11 shared techniques (26% overlap)
- APT19 China — 9 shared techniques (26% overlap)
- Higaisa South Korea — 10 shared techniques (25% overlap)
- BRONZE BUTLER China — 12 shared techniques (24% overlap)
Targets
Government · Private sector
Regions
Afghanistan · Armenia · Azerbaijan · Belarus · Belgium · Czech Republic · Greece · India · Iran · Italy · Kazakhstan · Kenya · Malaysia · Russia · South Africa · Suriname · Turkmenistan · Ukraine · United Kingdom · United States · Vietnam
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
TTPs — 22 techniques across 9 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1059.001PowerShell -
T1059.005Visual Basic -
T1203Exploitation for Client Execution -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.013Encrypted/Encoded File -
T1218.005Mshta -
T1218.010Regsvr32 -
T1221Template Injection
Credential Access
-
T1555.003Credentials from Web Browsers
Discovery
-
T1057Process Discovery -
T1069.002Domain Groups -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1518Software Discovery
Collection
-
T1005Data from Local System
Command and Control
-
T1071.001Web Protocols -
T1090.003Multi-hop Proxy -
T1102Web Service -
T1573.001Symmetric Cryptography
Tools & malware (3)
PowerShower · VBShower · LaZagne